Phishing red flags checklist: 15 signs an email is fake

The 2026 phishing red flags checklist: 15 signs an email is fake — spoofed senders, fake urgency, mismatched links, changed bank details — and what to do next.

The phishing red flags that catch nearly every fake email group into four clusters: the sender, the pressure, the link and the money. If an email trips three or more, treat it as hostile until someone verifies it through another channel — and in 2026, when AI writes flawless prose, the flags that remain reliable are almost all structural.

Key takeaways

The sender red flags

  1. Display name and address disagree. A message signed CFO Sarah Nguyen but sent from a personal Gmail address is not your CFO.
  2. Look-alike domains. Swapped letters and added words — yourbank.com.au versus your-bank.com.au — are the oldest trick and still among the most profitable.
  3. Reply-to differs from the sender. The reply goes to a different address than the one the message arrived from; check before answering.
  4. Unexpected external banner or unknown correspondent. An external-sender tag on mail you expected to be internal, or an unknown sender asking for anything.

The pressure red flags

  1. A deadline measured in hours. Genuine businesses give you time to verify; fraudsters give you minutes.
  2. Secrecy instructions. Keep this between us, do not loop in IT, the CEO is in meetings all day.
  3. Threats of consequence. Account closure, penalty, legal action, an expired subscription — the pressure is the payload.
  4. Something for nothing. Refunds, prizes or tax rebates you never applied for.

The link and attachment red flags

  1. Hover reveals a mismatch. The text says your bank; the tooltip shows a hyphenated string on a different domain.
  2. Shortened or wrapped links. Shortener links and surprise redirects hide the destination on purpose.
  3. Unexpected attachments. Especially invoices you never ordered, zip archives and files that open a browser login page.
  4. QR codes inside email. They push the action onto your phone, away from the corporate filter that would have caught it.

The money and data red flags

  1. Changed bank details. Any change to payment instructions is verified by phone, using a number you already had — never one from the email.
  2. Requests for credentials or codes. Nobody legitimate needs your password, an MFA code or a gift card purchase.
  3. Personal data requests. Staff lists, customer contact details, tax file numbers — especially combined with urgency.

How to use the checklist

SituationMove
One or two flagsVerify through a known channel before acting
Three or more flagsTreat as hostile, report, do not interact
Payment details changedPhone the known number before any payment
Credentials already enteredIncident response, immediately

Why the checklist still works in the AI era

Generated phishing has erased the typo tell: messages in 2026 are grammatically flawless and personalised with scraped details. What AI has not erased is the structural mismatch — the reply-to, the domain, the changed account, the urgency. Those live in the attacker's infrastructure and timeline, not their prose. Verizon's 2025 Data Breach Investigations Report analysed 12,195 confirmed breaches and again found a human element in roughly 60% of them (full report PDF); the checklist exists because that 60% is decided in seconds at the desk, not in a security review.

Turning the checklist into a reflex

A checklist in a policy document stops zero phishing. The reflex forms through repetition: monthly micro-lessons built around real local lures, simulations that exercise exactly these flags, and a report button that makes the correct action one click. Cyber Aware's security awareness training sequences monthly lessons and simulations this way, and the platform comparison shows how vendors differ on the same-day coaching loop that makes the lesson stick.

What to do the moment you spot a red flag

Do not click, do not forward to colleagues, do not reply to test it. Use the report button so the message is captured and pulled from other mailboxes, then tell the recipient's manager or IT by voice. If you already clicked or entered credentials, skip the checklist and go straight to credential resets and your incident process.

FAQ

What are the most common phishing red flags? Sender-address mismatch, artificial urgency, link destinations that disagree with the link text, and any change to payment details.

What is the single most reliable red flag? A request that bypasses normal process — changed bank details or credentials asked for by email. Verification through a known channel defeats it.

Can AI-written phishing be spotted? Yes — structural flags still work. Perfect grammar is no longer a sign of legitimacy, so judge the sender, the links and the request, not the prose.

Do the same flags apply to SMS and chat messages? Mostly. Urgency, links and payment requests transfer directly; sender checks become number and account checks.

What should I do if I already clicked? Reset the credentials for any account you touched, report it immediately, and follow your incident steps — speed limits the damage more than anything else.

How often should staff rehearse the checklist? Monthly. A lesson and one simulation per month keep the flags current with what attackers are actually sending in 2026.

One last thing

The most dangerous email is not the obvious scam. It is the plausible one that trips exactly one flag — a changed bank detail on an otherwise perfect invoice thread. Processes beat perception: verification steps for payments and credentials catch what reading never will.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.